moonpay-commerce-r829wci3x-heliofi.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonpay-commerce-r829wci3x-heliofi.vercel.app
This page appears to present itself as a MoonPay Commerce login or onboarding portal related to cryptocurrency payments. The visible content references crypto checkout, pay links, subscriptions, and merchant deposits, which suggests a financial-services or crypto-commerce workflow aimed at businesses or users accepting digital-asset payments.
However, the site is hosted on a vercel.app subdomain rather than an obvious primary MoonPay-owned domain, while also using MoonPay branding and references to commerce.moonpay.com. Based on the domain structure, page title, and screenshot, it may be a branded landing page or a look-alike page designed to resemble a legitimate crypto payment service. The operator cannot be independently confirmed from the scan data alone.
The page layout is minimal and centers on collecting an email address or prompting wallet sign-in, which is consistent with account access or lead-capture flows. Because the branding references a known crypto payments company while the hostname sits on a third-party hosting subdomain, extra caution would generally be warranted when interpreting who actually controls the page.
Safety Assessment for moonpay-commerce-r829wci3x-heliofi.vercel.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. The page also appears to use the branding of a known crypto payments service while operating from a vercel.app subdomain, which may indicate a look-alike setup intended to collect credentials or wallet access details.
The malware scan did not detect malicious files in the sampled page resources, but that does not offset the stronger phishing-related consensus from the broader reputation data. In addition, the domain's IP address is listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still worth noting as a minor caution.
The screenshot shows a login-style interface requesting an email address and offering wallet sign-in, which can be sensitive actions on a page with disputed reputation. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is hosted on Vercel infrastructure and resolves to IP address 64.29.17.195 in the United States. It presents a valid SSL/TLS certificate issued by Google Trust Services, expiring in September 2026. The page appears to be built with a modern JavaScript framework, with multiple _next/static assets indicating a Next.js deployment.
DNSSEC is unsigned, which is common but provides no additional DNS integrity protection. WHOIS data indicates the underlying domain has existed for several years, although that age applies to the parent domain context and does not necessarily establish trust for this specific hosted subdomain. The main technical concern from this scan is not transport security, but the combination of brand-style presentation on a hosted subdomain and the volume of phishing-related detections.
Share your experience with this website. Was it safe? Did you encounter any issues?